Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-6353— Tyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication bypass

CVSS 5.3 · Medium EPSS 1.58% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-6353

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tyler Technologies Civil and Criminal Electronic Filing 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tyler Technologies Civil and Criminal Electronic Filing是Tyler Technologies公司的用于刑事和民事案件的电子归档系统。 Tyler Technologies Civil and Criminal Electronic Filing存在安全漏洞。远程攻击者利用该漏洞通过操纵Upload.aspx的enky参数来上传、删除和查看文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Tyler TechnologiesCivil and Criminal Electronic Filing 0 -

II. Public POCs for CVE-2023-6353

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-6353

登录查看更多情报信息。

Same Patch Batch · Tyler Technologies · 2023-11-30 · 6 CVEs total

CVE-2023-63425.3 MEDIUMTyler Technologies Court Case Management Plus "pay for print" allows authentication bypass
CVE-2023-63435.3 MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allo
CVE-2023-63445.3 MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and
CVE-2023-63545.3 MEDIUMTyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authenticat
CVE-2023-63755.3 MEDIUMTyler Technologies Magistrate Court Case Management Plus stores backups insecurely

IV. Related Vulnerabilities

V. Comments for CVE-2023-6353

No comments yet


Leave a comment